Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

1426 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.20%—Wpbakery Page BuilderAI1/9/20261/9/2026
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
AplazadaMedia (6.1)0.38%—Codesmiths User Profile BuilderAI1/9/20261/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.4)0.33%—Codesigner User Profile BuilderAI1/9/20261/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode Attribute in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaMedia (6.9)0.41%—Extendthemes Kubio AI Website BuilderAI31/8/20268/9/2026
Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1.
AplazadaMedia (5.5)0.50%—Cozmoslabs Profile BuilderAI31/8/202631/8/2026
A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is…
AplazadaAlta (7)0.17%—Electron-builderAIMicrosoft Windows InstallerAI30/8/20261/9/2026
SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves these calls using a search path that…
AplazadaAlta (8.2)0.32%—Codesmiths User Profile BuilderAI29/8/202631/8/2026
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other…
AplazadaMedia (6.6)0.42%—Cozmoslabs User Profile BuilderAI29/8/202631/8/2026
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is…
AplazadaMedia (6.8)0.43%—User Profile BuilderAI29/8/202631/8/2026
The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by…
AplazadaMedia (4.3)0.15%—Shopapper Mobile APP BuilderAI27/8/202628/8/2026
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock…
AplazadaMedia (6.4)0.36%—Greenshift Animation AND Page Builder BlocksAI26/8/202626/8/2026
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up to, and including, 12.8.9. This is due to insufficient sanitization of API responses before output via innerHTML. This makes it possible for authenticated…
AplazadaCrítica (9.8)0.92%—AvadaAIAvada Fusion BuilderAI26/8/202627/8/2026
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it…
AplazadaAlta (8.6)0.53%—Shopbuilder PROAI24/8/202624/8/2026
Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.
AplazadaCrítica (9.3)0.39%—Joomlack Page Builder CKAI24/8/202626/8/2026
Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model.
AplazadaMedia (5.3)0.44%—Joomlack Page Builder CKAI24/8/202626/8/2026
Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter.
AplazadaMedia (4.3)0.27%—Brave Popup BuilderAI23/8/202626/8/2026
Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.
AplazadaAlta (7.1)0.25%—Brave Popup BuilderAI23/8/202626/8/2026
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
AplazadaMedia (5.3)0.56%—Themify BuilderAI22/8/202624/8/2026
The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the stored Themify Builder styling…
Pendiente de análisisBaja (2.1)0.22%—Joshnuss XML BuilderAI21/8/202624/8/2026
XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.element/1, XmlBuilder.element/2, XmlBuilder.element/3.…
Pendiente de análisisBaja (2.1)0.22%—Joshnuss XML BuilderAI21/8/202624/8/2026
XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape/1. The escape/1 clause for {:cdata, data} in…
Pendiente de análisisBaja (2.1)0.19%—Joshnuss XML BuilderAI21/8/202624/8/2026
Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape_string/1,…
AplazadaMedia (4.3)0.25%—Wptablebuilder WP Table BuilderAI18/8/202620/8/2026
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
AplazadaCrítica (9.3)0.39%—Joomlack Page Builder CKAI17/8/202626/8/2026
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.
AplazadaMedia (6.4)0.32%—Bold-themes Bold Page BuilderAI16/8/202620/8/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and including, 5.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaAlta (7.5)0.45%—Webtoffee Extra Product Options Builder FOR WoocommerceAI16/8/202626/8/2026
The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product Options Builder for WooCommerce WordPress…